Out-of-bounds read in Intel products - CVE-2020-24506

 

Out-of-bounds read in Intel products - CVE-2020-24506

Published: June 17, 2021


Vulnerability identifier: #VU54199
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24506
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in a subsystem. A local administrator can trigger out-of-bounds read error and read contents of memory on the system.


Affected software

Intel Server Platform Services Firmware
Intel C240 Series Chipset
Intel Atom Processor P5000 Series
Intel C620A Series Chipset
3rd Generation Intel Xeon Scalable Processors
Intel 200 Series Chipset
8th Generation Intel Core Processors
Intel 100 Series Chipset
7th Generation Intel Core Processors
Intel C420 Chipset
Intel X299 Chipset
Intel C620 Series Chipset
Converged Security and Management Engine (CSME)
Intel 300 Series Chipset
Intel Celeron Processor 4000 Series
10th Generation Intel Core Processors
Intel Core i3 L13G4
Intel Core i5 L16G7
Intel Pentium Processor Silver Series
Intel Celeron Processor N Series
Intel Xeon W Processor 1200
Intel Xeon W Processor 10000
Intel 400 Series Chipset
Intel Celeron Processor G Series
Intel Pentium Gold Processor Series
Intel Celeron Processor 6000 Series
11th Generation Intel Core Processors
SIMATIC IPC527GE
SINUMERIK ONE PPU 1740
SINUMERIK ONE / SINUMERIK 840D sl Handheld Terminal HT 10
SINUMERIK MC MCU 1720
SINUMERIK 828D HW PPU.4
SIMATIC S7-1500 CPU 1518F-4 PN-DP MFP
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
SIMATIC Drive Controller
SIMATIC IPC477E Pro
SIMATIC IPC127E
SIMATIC Field PG M6
SIMATIC Field PG M5
SIMATIC IPC627E
SIMATIC IPC647E
SIMATIC IPC677E
SIMATIC IPC847E
SIMATIC ITP1000
SIMATIC IPC547G
SIMATIC IPC477E
SIMATIC IPC427E
SIMATIC ET 200SP Open Controller CPU 1515SP PC2
Edgeline EL300 Converged Edge System
Dell EMC VxRail Appliance

How to mitigate CVE-2020-24506

Install updates from vendor's website.

Intel Server Platform Services Firmware - addressed in versions SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0
Intel C240 Series Chipset - addressed in versions SPS_E3_05.01.04.300.0, 12.0.81
Intel Atom Processor P5000 Series - update to SPS_SoC-A_05.00.03.091.0
Intel C620A Series Chipset - addressed in versions SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0
3rd Generation Intel Xeon Scalable Processors - addressed in versions SPS_E5_04.04.03.263.0, SPS_E5_04.04.04.023.0
Intel 200 Series Chipset - update to 11.8.86
8th Generation Intel Core Processors - update to 11.8.86
Intel 100 Series Chipset - update to 11.8.86
7th Generation Intel Core Processors - update to 11.8.86
Intel C420 Chipset - update to 11.12.86
Intel X299 Chipset - update to 11.12.86
Intel C620 Series Chipset - update to 11.22.86
Converged Security and Management Engine (CSME) - addressed in versions 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32
Intel 300 Series Chipset - update to 12.0.81
Intel Celeron Processor 4000 Series - update to 12.0.81
10th Generation Intel Core Processors - update to 13.0.47
Intel Core i3 L13G4 - update to 13.30.17
Intel Core i5 L16G7 - update to 13.30.17
Intel Pentium Processor Silver Series - update to 13.50.11
Intel Celeron Processor N Series - update to 13.50.11
Intel Xeon W Processor 1200 - update to 14.1.53
Intel Xeon W Processor 10000 - update to 14.1.53
Intel 400 Series Chipset - update to 14.1.53
Intel Celeron Processor G Series - update to 14.1.53
Intel Pentium Gold Processor Series - update to 14.5.32
Intel Celeron Processor 6000 Series - update to 15.0.22
11th Generation Intel Core Processors - update to 15.0.22
Edgeline EL300 Converged Edge System - addressed in versions EL01_1.40, 11.8.86.3909
Dell EMC VxRail Appliance - update to 7.0.300
SIMATIC IPC627E - update to 25.02.10
SIMATIC IPC647E - update to 25.02.10
SIMATIC IPC677E - update to 25.02.10
SIMATIC IPC847E - update to 25.02.10

External References

Related Security Bulletins